CVE-2023-31000 to CVE-2023-31999
142 CVEs with public proof-of-concept exploits.
- CVE-2023-310594 PoCsRepetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by…
- CVE-2023-310601 PoCRepetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.
- CVE-2023-310611 PoCRepetier Server through 1.4.10 does not have CSRF protection.
- CVE-2023-310672 PoCsAn issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories…
- CVE-2023-310681 PoCAn issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories…
- CVE-2023-310691 PoCAn issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the…
- CVE-2023-310961 PoCAn issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege…
- CVE-2023-311261 PoCImproper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml
- CVE-2023-311281 PoCNextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection
- CVE-2023-311321 PoCCacti Privilege Escalation
- CVE-2023-311921 PoCAn information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted…
- CVE-2023-311941 PoCAn improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted…
- CVE-2023-312421 PoCAn authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A…
- CVE-2023-312471 PoCA memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A…
- CVE-2023-313201 PoCImproper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting…
- CVE-2023-313461 PoCFailure to initializememory in SEV Firmware may allow a privileged attacker to access stale datafrom other guests.
- CVE-2023-313552 PoCsImproper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially…
- CVE-2023-314192 PoCsElasticsearch StackOverflow vulnerability
- CVE-2023-314332 PoCsA SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute…
- CVE-2023-314342 PoCsThe parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in evasys before 8.2…
- CVE-2023-314352 PoCsMultiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys…
- CVE-2023-314451 PoCCassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows…
- CVE-2023-314462 PoCsIn Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized.…
- CVE-2023-314611 PoCAttackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a…
- CVE-2023-314621 PoCAn issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writable for all users…
- CVE-2023-314652 PoCsAn issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is…
- CVE-2023-314661 PoCAn XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance report" and…
- CVE-2023-314682 PoCsAn issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH"…
- CVE-2023-314721 PoCAn issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere…
- CVE-2023-314731 PoCAn issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere…
- CVE-2023-314751 PoCAn issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item…
- CVE-2023-314761 PoCAn issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be…
- CVE-2023-314771 PoCA path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an…
- CVE-2023-314782 PoCsAn issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the…
- CVE-2023-314891 PoCAn issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
- CVE-2023-314901 PoCAn issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
- CVE-2023-314921 PoCZoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized…
- CVE-2023-314971 PoCIncorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to…
- CVE-2023-314981 PoCA privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary…
- CVE-2023-315021 PoCAltenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component…
- CVE-2023-315051 PoCAn arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain…
- CVE-2023-315301 PoCMotorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
- CVE-2023-315411 PoCA unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for…
- CVE-2023-315432 PoCsA dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the…
- CVE-2023-315461 PoCCross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
- CVE-2023-315481 PoCA stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute…
- CVE-2023-315551 PoCpodofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.
- CVE-2023-315561 PoCpodofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.
- CVE-2023-315661 PoCPodofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().
- CVE-2023-315671 PoCPodofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.
- CVE-2023-315681 PoCPodofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
- CVE-2023-315841 PoCGitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User…
- CVE-2023-315871 PoCTenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at…
- CVE-2023-315941 PoCIC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
- CVE-2023-315951 PoCIC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.
- CVE-2023-316062 PoCsA Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This…
- CVE-2023-316071 PoCAn issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316081 PoCAn issue in the artm_div_int component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316091 PoCAn issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316101 PoCAn issue in the _IO_default_xsputn component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS)…
- CVE-2023-316111 PoCAn issue in the __libc_longjmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316121 PoCAn issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316131 PoCAn issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS)…
- CVE-2023-316151 PoCAn issue in the chash_array component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316161 PoCAn issue in the bif_mod component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2023-316171 PoCAn issue in the dk_set_delete component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316181 PoCAn issue in the sqlc_union_dt_wrap component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS)…
- CVE-2023-316191 PoCAn issue in the sch_name_to_object component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS)…
- CVE-2023-316201 PoCAn issue in the dv_compare component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316211 PoCAn issue in the kc_var_col component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316221 PoCAn issue in the sqlc_make_policy_trig component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS)…
- CVE-2023-316231 PoCAn issue in the mp_box_copy component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316241 PoCAn issue in the sinv_check_exp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316251 PoCAn issue in the psiginfo component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2023-316261 PoCAn issue in the gpf_notice component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316271 PoCAn issue in the strhash component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2023-316281 PoCAn issue in the stricmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2023-316291 PoCAn issue in the sqlo_union_scope component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316301 PoCAn issue in the sqlo_query_spec component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-316311 PoCAn issue in the sqlo_preds_contradiction component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service…
- CVE-2023-316342 PoCsIn TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the…
- CVE-2023-316641 PoCA reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers…
- CVE-2023-316771 PoCInsecure permissions in luowice 3.5.18 allow attackers to view information for other alarm devices via modification of the eseeid parameter.
- CVE-2023-316781 PoCIncorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.
- CVE-2023-316791 PoCIncorrect access control in Videogo v6.8.1 allows attackers to access images from other devices via modification of the Device Id parameter.
- CVE-2023-316891 PoCIn Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish…
- CVE-2023-316982 PoCsBludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that…
- CVE-2023-316991 PoCChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.
- CVE-2023-317001 PoCTP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.
- CVE-2023-317011 PoCTP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.
- CVE-2023-317023 PoCsSQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire…
- CVE-2023-317033 PoCsCross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker…
- CVE-2023-317041 PoCSourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate…
- CVE-2023-317081 PoCA Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a crafted HTML file…
- CVE-2023-317142 PoCsChitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
- CVE-2023-317161 PoCFUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
- CVE-2023-317172 PoCsA SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
- CVE-2023-317182 PoCsFUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
- CVE-2023-317191 PoCFUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
- CVE-2023-317232 PoCsyasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c.
- CVE-2023-317242 PoCsyasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c.
- CVE-2023-317252 PoCsyasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at…
- CVE-2023-317401 PoCThere is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management…
- CVE-2023-317411 PoCThere is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management…
- CVE-2023-317421 PoCThere is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web…
- CVE-2023-317474 PoCsWondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component…
- CVE-2023-317482 PoCsInsecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.
- CVE-2023-317532 PoCsSQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
- CVE-2023-317541 PoCOptimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.
- CVE-2023-317561 PoCA command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <=…
- CVE-2023-317571 PoCDedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
- CVE-2023-318261 PoCSkyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute…
- CVE-2023-318511 PoCCudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.
- CVE-2023-318521 PoCCudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.
- CVE-2023-318531 PoCCudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.
- CVE-2023-318711 PoCOpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to…
- CVE-2023-318732 PoCsGin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
- CVE-2023-318741 PoCYank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process').
- CVE-2023-319025 PoCsRPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
- CVE-2023-319032 PoCsGuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
- CVE-2023-319041 PoCsavysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.
- CVE-2023-319071 PoCJerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at…
- CVE-2023-319081 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component ecma_builtin_typedarray_prototype_sort.
- CVE-2023-319101 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at…
- CVE-2023-319131 PoCJerryscript 3.0 *commit 1a2c047) was discovered to contain an Assertion Failure via the component parser_parse_class at…
- CVE-2023-319161 PoCJerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the jmem_heap_finalize at jerry-core/jmem/jmem-heap.c.
- CVE-2023-319181 PoCJerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the parser_parse_function_arguments at…
- CVE-2023-319191 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the jcontext_raise_exception at…
- CVE-2023-319201 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the vm_loop at jerry-core/vm/vm.c.
- CVE-2023-319211 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_big_uint_div_mod at…
- CVE-2023-319221 PoCQuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
- CVE-2023-319231 PoCSuprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker…
- CVE-2023-319401 PoCSQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id…
- CVE-2023-319721 PoCyasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties…
- CVE-2023-319731 PoCyasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third…
- CVE-2023-319741 PoCyasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute…
- CVE-2023-319791 PoCCatdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
- CVE-2023-319811 PoCSngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
- CVE-2023-319821 PoCSngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c.
- CVE-2023-319831 PoCA Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the…
- CVE-2023-319851 PoCA Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the…
- CVE-2023-319861 PoCA Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the…